So, every time one of these files is opened, the worm is activated. The worm checks which file is opened, while copying itself. If this is a REGEDIT or REG file, the worm tries to stop the system. But if it an EXE file, the worm executes its payload. In any other case, is creates a \Recycled\ directory, renames the startfiles arbitrarily and places them in the directory. Moreover, it copies itself with the same name and .exe extension in \Recycled\.